Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 245

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
Amazon launches GLP-1 weight loss program, promising 'fast, convenient' access
Gates Foundation reviewing Jeffrey Epstein ties, will slash 20% of staff, WSJ reports
Did this crow poop on me deliberately?
Is it okay to leave the toilet seat up in a shared office space?
Google recaptcha V3 here
Movie: Rabbit Trap
Movie: My Life as a Dog
European stocks set to open lower as Trump refuses to lift Strait of Hormuz blockade
Japan's Nikkei 225 rises to record high as Trump extends Iran ceasefire
Apple incoming CEO John Ternus faces a defining challenge: Fixing the company's AI strategy